Firewall is still not completely happy, it seems. Hereâs the deets:
firewall config
config defaults
option input âACCEPTâ
option output âACCEPTâ
option forward âREJECTâ
option synflood_protect â1â
config zone
option name âlanâ
list network âlanâ
option input âACCEPTâ
option output âACCEPTâ
option forward âACCEPTâ
config zone
option name âwanâ
list network âwanâ
list network âwan6â
option input âREJECTâ
option output âACCEPTâ
option forward âREJECTâ
option masq â1â
option mtu_fix â1â
option sentinel_dynfw â1â
option sentinel_fwlogs â1â
option sentinel_minipot â1â
option haas_proxy â1â
config forwarding
option src âlanâ
option dest âwanâ
config rule
option name âAllow-DHCP-Renewâ
option src âwanâ
option proto âudpâ
option dest_port â68â
option target âACCEPTâ
option family âipv4â
config rule
option name âAllow-Pingâ
option src âwanâ
option proto âicmpâ
option icmp_type âecho-requestâ
option family âipv4â
option target âACCEPTâ
config rule
option name âAllow-IGMPâ
option src âwanâ
option proto âigmpâ
option family âipv4â
option target âACCEPTâ
config rule
option name âAllow-DHCPv6â
option src âwanâ
option proto âudpâ
option dest_port â546â
option family âipv6â
option target âACCEPTâ
config rule
option name âAllow-MLDâ
option src âwanâ
option proto âicmpâ
option src_ip âfe80::/10â
list icmp_type â130/0â
list icmp_type â131/0â
list icmp_type â132/0â
list icmp_type â143/0â
option family âipv6â
option target âACCEPTâ
config rule
option name âAllow-ICMPv6-Inputâ
option src âwanâ
option proto âicmpâ
list icmp_type âecho-requestâ
list icmp_type âecho-replyâ
list icmp_type âdestination-unreachableâ
list icmp_type âpacket-too-bigâ
list icmp_type âtime-exceededâ
list icmp_type âbad-headerâ
list icmp_type âunknown-header-typeâ
list icmp_type ârouter-solicitationâ
list icmp_type âneighbour-solicitationâ
list icmp_type ârouter-advertisementâ
list icmp_type âneighbour-advertisementâ
option limit â1000/secâ
option family âipv6â
option target âACCEPTâ
config rule
option name âAllow-ICMPv6-Forwardâ
option src âwanâ
option dest â*â
option proto âicmpâ
list icmp_type âecho-requestâ
list icmp_type âecho-replyâ
list icmp_type âdestination-unreachableâ
list icmp_type âpacket-too-bigâ
list icmp_type âtime-exceededâ
list icmp_type âbad-headerâ
list icmp_type âunknown-header-typeâ
option limit â1000/secâ
option family âipv6â
option target âACCEPTâ
config rule
option name âAllow-IPSec-ESPâ
option src âwanâ
option dest âlanâ
option proto âespâ
option target âACCEPTâ
config rule
option name âAllow-ISAKMPâ
option src âwanâ
option dest âlanâ
option dest_port â500â
option proto âudpâ
option target âACCEPTâ
config rule
option name âSupport-UDP-Tracerouteâ
option src âwanâ
option dest_port â33434:33689â
option proto âudpâ
option family âipv4â
option target âREJECTâ
option enabled â0â
config include
option path â/etc/firewall.userâ
config zone âguest_turrisâ
option input âREJECTâ
option forward âREJECTâ
option output âACCEPTâ
option enabled â1â
list network âguest_turrisâ
option name âtr_guestâ
config forwarding âguest_turris_forward_wanâ
option name âguest to wan forwardâ
option dest âwanâ
option enabled â1â
option src âtr_guestâ
config rule âguest_turris_dns_ruleâ
option name âguest dns ruleâ
option proto âtcpudpâ
option dest_port â53â
option target âACCEPTâ
option src âtr_guestâ
config rule âguest_turris_dhcp_ruleâ
option name âguest dhcp ruleâ
option proto âudpâ
option src_port â67-68â
option dest_port â67-68â
option target âACCEPTâ
option src âtr_guestâ
config rule âwan_ssh_turris_ruleâ
option name âwan_ssh_turris_ruleâ
option target âACCEPTâ
option dest_port â22â
option proto âtcpâ
option src âwanâ
option enabled â0â
config rule âwan_http_turris_ruleâ
option name âwan_http_turris_ruleâ
option target âACCEPTâ
option dest_port â80â
option proto âtcpâ
option src âwanâ
option enabled â0â
config rule âwan_https_turris_ruleâ
option name âwan_https_turris_ruleâ
option target âACCEPTâ
option dest_port â443â
option proto âtcpâ
option src âwanâ
option enabled â0â
config rule âturris_wan_6in4_ruleâ
option family âipv4â
option proto â41â
option target âACCEPTâ
option src âwanâ
option src_ip â1.1.1.1â
config redirect
option dest_port â22â
option src âwanâ
option name âSSH redirectâ
option src_dport â122â
option target âDNATâ
option dest âlanâ
list proto âtcpâ
option enabled â0â
config zone âvpn_turrisâ
option enabled â1â
option name âvpn_turrisâ
option input âACCEPTâ
option forward âREJECTâ
option output âACCEPTâ
option masq â1â
list network âvpn_turrisâ
config rule âvpn_turris_ruleâ
option name âvpn_turris_ruleâ
option target âACCEPTâ
option proto âudpâ
option src âwanâ
option dest_port â1194â
config forwarding âvpn_turris_forward_lan_inâ
option enabled â1â
option src âvpn_turrisâ
option dest âlanâ
config forwarding âvpn_turris_forward_lan_outâ
option enabled â1â
option src âlanâ
option dest âvpn_turrisâ
config forwarding âvpn_turris_forward_wan_outâ
option enabled â1â
option src âvpn_turrisâ
option dest âwanâ
config zone âturris_vpn_clientâ
option name âtr_vpn_clâ
option input âREJECTâ
option output âACCEPTâ
option forward âREJECTâ
option masq â1â
config forwarding âturris_vpn_client_forwardâ
option src âlanâ
option dest âtr_vpn_clâ
config include âminiupnpdâ
option type âscriptâ
option path â/usr/share/miniupnpd/firewall.includeâ
option family âanyâ
option reload â1â
config include âbcp38â
option type âscriptâ
option path â/usr/lib/bcp38/run.shâ
config include
option path â/etc/firewall.fail2banâ
option enabled â1â
option reload â1â
config include âsentinel_firewallâ
option type âscriptâ
option path â/usr/libexec/sentinel/firewall.shâ